Stories
Slash Boxes
Comments

SoylentNews is people

posted by janrinok on Monday January 30 2023, @07:39PM   Printer-friendly
from the Security dept.

I found this on one of Devuan's forums

There's a software package called Zeitgeist that's been finding its way into nearly every Linux and BSD package repository. It's also on Devuan. Be sure to read the note at the bottom of this post even if you are not impacted by this.

It reads your emails, it monitors the websites you visit, listens to private conversations, and logs the files on your computer. and then it shares this information freely over D-Bus to any application that wishes to use it. You are given no warning and have no option to say which software can access it, and which can't. Any software can access D-bus, including closed-source software like Discord or Telegram (whether they do or not, who knows).

From the description, it looks as if it is designed to make spyware's job easy. Do you have it on your system? Do you want it on your system?

[Editor's Comment: The package has been around for quite some time (since at least 2012) without any security problems being reported. Ubuntu's repo describes it as:

Zeitgeist is a service which logs the user's activities and events (files opened, websites visited, conversations held with other people, etc.) and makes the relevant information available to other applications.

It does not appear to be installed as default on the small number of distros that I have looked at but it might be installed on others.]


Original Submission

 
This discussion was created by janrinok (52) for logged-in users only, but now has been archived. No new comments can be posted.
Display Options Threshold/Breakthrough Mark All as Read Mark All as Unread
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
  • (Score: 3, Informative) by corey on Tuesday January 31 2023, @08:38PM (1 child)

    by corey (2202) on Tuesday January 31 2023, @08:38PM (#1289523)

    Certainly does lower productivity. On my corporate Windows laptop, they have a few security packages installed plus antivirus software by Sophos. It’s a 10th gen i7 with 32GB RAM and the fan in it runs pretty much constant all day every day. I’m often opening task manager and seeing what’s going on and it’s either an inventory scanner, virus scanner, windows modules installer, auditor running. It seems to scan every file open access and saving so there’sa delay in everything. It is pretty borked, it runs very slow most of the time for what it is and my home PC running Windows, which is a 2nd gen i5 overlocked, is significantly faster and snappier. Additionally, I can’t either install anything nor run any executable that’s in some white list. Thankfully I can still run Putty and Firefox but one day I tried to ask if I could run mupdf (because it’s infinitely faster to open and operate than Adobe Acrobat), but I had to fill out forms, get them signed by senior management and then wait for IT to get around to installing it or white listing it. Really is a joke. Think I’m going to go contractor and BYO hardware.

    Starting Score:    1  point
    Moderation   +1  
       Informative=1, Total=1
    Extra 'Informative' Modifier   0  
    Karma-Bonus Modifier   +1  

    Total Score:   3  
  • (Score: 2) by RS3 on Tuesday January 31 2023, @09:49PM

    by RS3 (6367) on Tuesday January 31 2023, @09:49PM (#1289541)

    I'm somewhat too passionate about machines, tools, etc., to deal with all of that. I'd have found another job long ago. They probably added all that stuff over time so you'd acclimate. Ugh. One of my great passions (and I'm not willing to undergo ECT to de-program my brain and remove it) is productivity and efficiency- mainly for myself. The rare times I've been in any kind of supervisory role I've never ever pressured anyone to work harder, faster, etc. I'm too busy doing my own thing to notice anyway.

    I've had friends and coworkers who have a very good attitude about work- they just don't care about such things. They don't have the tools or parts or supplies or time or cleared path to get something done? Aaa, they're happy to sit and wait until management does their jobs. I wish I didn't care.

    I'm curious- have you in any way documented, and/or communicated to IT and/or management about how you're being slowed down by all of the crapware on your company issued computer?